Description
WinGate v9.4.1.5998 has insecure permissions for the installation directory, which allows local users to gain privileges by replacing an executable file with a Trojan horse.
Exploits (1)
References (3)
Scores
CVSS v3
7.8
EPSS
0.0026
EPSS Percentile
48.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-732
Status
published
Products (1)
qbik/wingate
9.4.1.5998
Published
Jun 08, 2020
Tracked Since
Feb 18, 2026